I found these files bundled with an installer of browserair. It seems to be by a fake tech support company...
During installation, it drops a few files to the C:\Winodws folder.
Scans:
bs1.exe
https://www.virustotal.com/en/file/3cb1 ... 455138949/
MD5 Hash- a050a6b258a30b2a6f3740024308639c
SHA256 Hash-3cb16dc12599fd70be6a0de232ae00b5866b2f4d157d6618f45d09c77f1267d1
HardwareInformation.exe
https://www.virustotal.com/en/file/4e40 ... 455139092/
MD5 Hash- dc3dc7337c50bd367967a5fbaeb15d3c
SHA256 Hash- 4e4016e3aa516c122dba7716099a6da90e7f5ce0aa606a00a4f90bff4074cc20
Mint.exe
https://www.virustotal.com/en/file/9591 ... 455139181/
MD5 Hash- b234ebf2a1e9ceaa31809bab8d1eaa6f
SHA256 Hash- 95913c9975a6fb0208ed8f78ebdd989bf540a393941793ffbb2ce5f8f3efdcc5
MyTrayApp.exe
https://www.virustotal.com/en/file/3246 ... 455139287/
MD5 Hash- 51b03492d7b2ef71e34abc4eff9c9248
SHA256 Hash- 32467f8d021456b5d08472c26f9e2a833a45766c87843d2a0df5a2ff706e7659
sc.bat
https://www.virustotal.com/en/file/c7ff ... 455139387/
MD5 Hash- ad0290aabc56183e1e3441188b3b8925
SHA256 Hash- c7ff1999e57a66a89b6c7b4be9575e305df65336eedba92a5540e687d81ec4e1
Wimboldon.exe
https://www.virustotal.com/en/file/52df ... 455139470/
MD5 Hash- bd2ce90b77785bd71b5a67712ecbb0d6
SHA256 Hash- 52dfef92ba844e4c6c8b838518c5c1af5e632009bd2ddaa0a8a3afec8ab1f884
winupd.exe
https://www.virustotal.com/en/file/0e05 ... 455139677/
MD5 Hash- 6acbac07bbae07a146650d5bd94a88ce
SHA256 Hash- 0e05a276ef1017d550eca077fea3d64edd5551d5896b04f1b2d6c6a6fa893f96
setup.exe
https://www.virustotal.com/en/file/efed ... 455139807/
MD5 Hash- 6265446fdb04a0c2975eafe0f1071484
SHA256 Hash- b8a9ab84f15821ebbe48f21443d69e2e0a49817d
Article by malwarebytes:
https://blog.malwarebytes.org/fraud-sca ... h-a-twist/
During installation, it drops a few files to the C:\Winodws folder.
Scans:
bs1.exe
https://www.virustotal.com/en/file/3cb1 ... 455138949/
MD5 Hash- a050a6b258a30b2a6f3740024308639c
SHA256 Hash-3cb16dc12599fd70be6a0de232ae00b5866b2f4d157d6618f45d09c77f1267d1
HardwareInformation.exe
https://www.virustotal.com/en/file/4e40 ... 455139092/
MD5 Hash- dc3dc7337c50bd367967a5fbaeb15d3c
SHA256 Hash- 4e4016e3aa516c122dba7716099a6da90e7f5ce0aa606a00a4f90bff4074cc20
Mint.exe
https://www.virustotal.com/en/file/9591 ... 455139181/
MD5 Hash- b234ebf2a1e9ceaa31809bab8d1eaa6f
SHA256 Hash- 95913c9975a6fb0208ed8f78ebdd989bf540a393941793ffbb2ce5f8f3efdcc5
MyTrayApp.exe
https://www.virustotal.com/en/file/3246 ... 455139287/
MD5 Hash- 51b03492d7b2ef71e34abc4eff9c9248
SHA256 Hash- 32467f8d021456b5d08472c26f9e2a833a45766c87843d2a0df5a2ff706e7659
sc.bat
https://www.virustotal.com/en/file/c7ff ... 455139387/
MD5 Hash- ad0290aabc56183e1e3441188b3b8925
SHA256 Hash- c7ff1999e57a66a89b6c7b4be9575e305df65336eedba92a5540e687d81ec4e1
Wimboldon.exe
https://www.virustotal.com/en/file/52df ... 455139470/
MD5 Hash- bd2ce90b77785bd71b5a67712ecbb0d6
SHA256 Hash- 52dfef92ba844e4c6c8b838518c5c1af5e632009bd2ddaa0a8a3afec8ab1f884
winupd.exe
https://www.virustotal.com/en/file/0e05 ... 455139677/
MD5 Hash- 6acbac07bbae07a146650d5bd94a88ce
SHA256 Hash- 0e05a276ef1017d550eca077fea3d64edd5551d5896b04f1b2d6c6a6fa893f96
setup.exe
https://www.virustotal.com/en/file/efed ... 455139807/
MD5 Hash- 6265446fdb04a0c2975eafe0f1071484
SHA256 Hash- b8a9ab84f15821ebbe48f21443d69e2e0a49817d
Article by malwarebytes:
https://blog.malwarebytes.org/fraud-sca ... h-a-twist/
Attachments
The files that were dropped. PW=infected
(39.88 KiB) Downloaded 100 times
(39.88 KiB) Downloaded 100 times
The installer that dropped the files. PW=BrowserAir
(827.6 KiB) Downloaded 124 times
(827.6 KiB) Downloaded 124 times